Impact
An issue in libtiff permits an attacker to execute arbitrary code through the process_command_opts function used by tiffcrop. The flaw allows tailored command options to be interpreted in a way that can spawn code execution, potentially compromising the host system. The attack vector is inferred to be local or remote where an attacker can supply crafted command-line arguments to tiffcrop, though the description does not explicitly state network exposure. The primary consequence is loss of confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects installations of the libtiff library, with the specific version unspecified. Any system that uses the libtiff library and employs the tiffcrop tool is potentially vulnerable. No vendor product names or version ranges are provided.
Risk and Exploitability
The CVSS score is not supplied, and EPSS data is unavailable, but the nature of the flaw—allowing arbitrary code execution—implies a high exploitation potential if the vulnerable library is reachable. The issue is not listed in CISA’s KEV catalog, indicating no known active exploitation at the time of reporting. Users should treat this as a critical flaw that could be exploited by a local or remote user capable of running tiffcrop with crafted options.
OpenCVE Enrichment